7.1
CVE-2022-40525
- EPSS 0.05%
- Veröffentlicht 06.06.2023 08:15:11
- Zuletzt bearbeitet 21.11.2024 07:21:36
- Quelle product-security@qualcomm.com
- CVE-Watchlists
- Unerledigt
Information Exposure in Linux Networking Firmware
Information disclosure in Linux Networking Firmware due to unauthorized information leak during side channel analysis.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Qualcomm ≫ Csr8811 Firmware Version-
Qualcomm ≫ Ipq6000 Firmware Version-
Qualcomm ≫ Ipq6005 Firmware Version-
Qualcomm ≫ Ipq6010 Firmware Version-
Qualcomm ≫ Ipq6018 Firmware Version-
Qualcomm ≫ Ipq6028 Firmware Version-
Qualcomm ≫ Ipq9008 Firmware Version-
Qualcomm ≫ Ipq9574 Firmware Version-
Qualcomm ≫ Qca4024 Firmware Version-
Qualcomm ≫ Qca8072 Firmware Version-
Qualcomm ≫ Qca8075 Firmware Version-
Qualcomm ≫ Qca8081 Firmware Version-
Qualcomm ≫ Qca8082 Firmware Version-
Qualcomm ≫ Qca8084 Firmware Version-
Qualcomm ≫ Qca8085 Firmware Version-
Qualcomm ≫ Qca8386 Firmware Version-
Qualcomm ≫ Qcn5021 Firmware Version-
Qualcomm ≫ Qcn5022 Firmware Version-
Qualcomm ≫ Qcn5052 Firmware Version-
Qualcomm ≫ Qcn5121 Firmware Version-
Qualcomm ≫ Qcn5122 Firmware Version-
Qualcomm ≫ Qcn5152 Firmware Version-
Qualcomm ≫ Qcn6023 Firmware Version-
Qualcomm ≫ Qcn6024 Firmware Version-
Qualcomm ≫ Qcn9000 Firmware Version-
Qualcomm ≫ Qcn9022 Firmware Version-
Qualcomm ≫ Qcn9024 Firmware Version-
Qualcomm ≫ Qcn9070 Firmware Version-
Qualcomm ≫ Qcn9072 Firmware Version-
Qualcomm ≫ Qcn9074 Firmware Version-
Qualcomm ≫ Qcn9274 Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.147 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| product-security@qualcomm.com | 7.1 | 2.5 | 4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-668 Exposure of Resource to Wrong Sphere
The product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.